首页> 外文会议>International Conference on Computer Communications and Networks >An Improved Conflict Detection System with Periodic Cycle Treatment for Time-based Firewall Policies
【24h】

An Improved Conflict Detection System with Periodic Cycle Treatment for Time-based Firewall Policies

机译:一种改进的冲突检测系统,具有定期循环处理,用于时间为基础的防火墙策略

获取原文

摘要

Packet filtering provides initial layer of security based upon set of ordered filters called firewall policies. It is a difficult task for the administrator to manage and maintain firewall policies, as it is an error-prone and complicated task for a dynamic network environment. Conflict is a misconfiguration that happens when two or more filters overlap each other, resulting in shadowing and redundancy of the filters. On the other hand, time-based filters are introduced in CISCO firewalls and LINUX iptables to control network traffic on basis of time. It is very handy when a service is required to be available only at certain times of day or even certain days. Conflict occurs in time-based filters when two or more filters falls on same timing. It is required to detect conflicts in time-based filters. We have two main contributions in this paper. First, we propose a mapping mechanism to treat periodic cycles like every day or every specific day of the week, that removes the unnecessary computation. Second, we decompose time into intervals and compute the conflicting filters in each interval. We implemented the mechanism using time divisor comprises of seven primitive time-handling operations. We have also developed a prototype system to prove the effectiveness of the approach. We experimentally analyzed our system with different samples of time-based filters by varying the percentage of periodic cycles and thereby we clarified the effectiveness of the proposed mechanism.
机译:数据包过滤基于名为防火墙策略的订购过滤器集提供初始安全性。管理员要管理和维护防火墙策略是一项艰巨的任务,因为它是动态网络环境的错误易用和复杂的任务。当两个或多个过滤器相互重叠时,冲突是一种错误配置,导致过滤器的阴影和冗余。另一方面,在思科防火墙和Linux Iptables中引入了基于时间的过滤器,以基于时间控制网络流量。当需要在一定的一天甚至某些日子时提供服务时,它非常方便。当两个或多个过滤器下降到相同的时间时,冲突发生在基于时间的过滤器中。需要检测基于时间的过滤器冲突。我们在本文中有两个主要贡献。首先,我们提出了一种映射机制来治疗每天或本周每一日的每一天的周期性周期,从而消除不必要的计算。其次,我们将时间分解为间隔并在每个间隔中计算冲突的过滤器。我们使用时间除数来实现该机制,包括七个原始时间处理操作。我们还开发了一种原型系统来证明该方法的有效性。我们通过改变周期性周期的百分比,通过各种基于时间过滤器的不同样品进行了实验分析了我们的系统,从而阐明了所提出的机制的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号